blob: d6c8d6ec188fc67e911d11c50529286a1fccaa2d [file] [log] [blame]
From d8781da59fa5ac26895944d0471082c571f99223 Mon Sep 17 00:00:00 2001
From: Jens Axboe <>
Date: Tue, 26 May 2020 09:38:31 -0600
Subject: [PATCH] sched/fair: Don't NUMA balance for kthreads
commit 18f855e574d9799a0e7489f8ae6fd8447d0dd74a upstream.
Stefano reported a crash with using SQPOLL with io_uring:
BUG: kernel NULL pointer dereference, address: 00000000000003b0
CPU: 2 PID: 1307 Comm: io_uring-sq Not tainted 5.7.0-rc7 #11
RIP: 0010:task_numa_work+0x4f/0x2c0
Call Trace:
which is task_numa_work() oopsing on current->mm being NULL.
The task work is queued by task_tick_numa(), which checks if current->mm is
NULL at the time of the call. But this state isn't necessarily persistent,
if the kthread is using use_mm() to temporarily adopt the mm of a task.
Change the task_tick_numa() check to exclude kernel threads in general,
as it doesn't make sense to attempt ot balance for kthreads anyway.
Reported-by: Stefano Garzarella <>
Signed-off-by: Jens Axboe <>
Signed-off-by: Ingo Molnar <>
Acked-by: Peter Zijlstra <>
Signed-off-by: Paul Gortmaker <>
diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
index 95667bb3daca..9ca90fc24207 100644
--- a/kernel/sched/fair.c
+++ b/kernel/sched/fair.c
@@ -2659,7 +2659,7 @@ static void task_tick_numa(struct rq *rq, struct task_struct *curr)
* We don't care about NUMA placement if we don't have memory.
- if (!curr->mm || (curr->flags & PF_EXITING) || work->next != work)
+ if ((curr->flags & (PF_EXITING | PF_KTHREAD)) || work->next != work)